security

Secure Workload Software contains five serious flaws, with updates required even for SaaS customers

Cisco disclosed that its Secure Workload Software—formerly Tetration, a micro‑segmentation tool designed to block lateral movement—contains four critical vulnerabilities plus one high‑severity issue.

The two flawless‑score bugs, CVE‑2026-20315 and CVE‑2026-20317, both stem from improper access control. Cisco’s brief description notes that CVE‑2026-20315 “encompasses authorization, authentication, privileges, and bypasses,” while CVE‑2026-20317 involves “missing authentication, authentication bypass, and reliance on untrusted inputs.”

CVE‑2026-20231 received a 9.9 rating and concerns “Improper neutralization of special elements (covers command, OS, argument injection).”

CVE‑2026-20318, scored 9.6, is an improper input validation problem.

The lowest‑rated issue, CVE‑2026-20319 at 7.5, relates to “Improper restriction of operations within the bounds of a memory buffer,” including overflows and out‑of‑bounds writes.

Cisco offers Secure Workload Software as both a SaaS offering and an on‑premises product. The SaaS version has been patched, but customers must still upgrade the Agent and Connector components that interface with the cloud service.

On‑premises installations running version 3.10 or earlier should move to 3.10.9.1, while those on version 4.0 or later need to adopt 4.0.4.16 promptly.

Cisco announced the findings on Thursday, attributing the discovery to a thorough internal security review that combined existing testing processes with frontier AI models.

The company participates in Project Glasswing, which provides access to Anthropic’s powerful, non‑public Mythos bug‑finding model—suggesting that model may have contributed to the analysis.

Cisco reports that, to date, no malicious exploitation of these vulnerabilities has been observed.®

Source link

Exit mobile version